Falhas do tipo CWE-200

4.927 resultados

Exposição de informações sensíveis

A aplicação vaza dados sensíveis (senhas, tokens, PII, chaves de API) para usuários ou sistemas que não deveriam ter acesso. Ocorre quando controles de acesso falham, logs registram dados confidenciais, ou a informação fica visível em resposta HTTP, cache do navegador ou memória — criando oportunidade para roubo de credenciais e elevação de privilégio.

Exemplo

Um endpoint REST retorna o JSON de um usuário incluindo o hash de senha ou token de sessão sem autenticação adequada; ou um erro 500 exibe caminho completo de arquivos e variáveis de ambiente; ou um relatório PDF público contém CPF/CNPJ de clientes.

Como mitigar

Implemente controle de acesso rigoroso (verificar permissões antes de expor dados), remova dados sensíveis de respostas HTTP e logs (nunca logar senha ou token completo), use variáveis de ambiente para credenciais, habilite HTTPS e configure cache-control private, e realize teste de exposição de dados em todas as camadas (banco, API, frontend).

CVE-2023-27863MEDIUMIBM Spectrum Protect Plus Server information disclosureEPSS 0.6%CVE-2025-11647LOWTomofun Furbo 360/Furbo Mini GATT Service information disclosureEPSS 0.6%CVE-2023-46315—The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable DiEPSS 0.6%CVE-2024-4021MEDIUMKeenetic KN-1010/KN-1410/KN-1711/KN-1810/KN-1910 Configuration Setting ndmComponents.js information disclosureEPSS 0.6%CVE-2026-41323HIGHKyverno: ServiceAccount token leaked to external servers via apiCall service URLEPSS 0.6%CVE-2025-31492HIGHmod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected dataEPSS 0.6%CVE-2024-27947MEDIUMA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems could allow log messages to be forwardEPSS 0.6%CVE-2024-24548HIGHPayment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purchases merchandise usEPSS 0.6%CVE-2023-0614HIGHThe fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacEPSS 0.6%CVE-2026-7167MEDIUMMultiple vulnerabilities in the Assassin game by GaudireEPSS 0.6%CVE-2024-56136MEDIUM/api/v1/jwt/fetch_api_key endpoint can leak if an email address has an account in Zulip serverEPSS 0.6%CVE-2022-31095MEDIUMExposure of Sensitive Information in discourse-chatEPSS 0.6%CVE-2026-84134CRITICALOther issue in the Profile Backup componentEPSS 0.6%CVE-2024-27296MEDIUMDirectus version number disclosureEPSS 0.6%CVE-2023-26026MEDIUMIBM Planning Analytics Cartridge for Cloud Pak for Data information disclosureEPSS 0.6%CVE-2023-24959MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.6%CVE-2024-29036MEDIUMSaleor Storefront session leak in cacheEPSS 0.6%CVE-2026-13697HIGHundici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directivesEPSS 0.6%CVE-2023-22611HIGHA CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information disclosure when specEPSS 0.6%CVE-2026-92708HIGHdevalue: Cross-request process memory disclosure in devalue when `stringify` / `uneval` serialize Node BuffersEPSS 0.6%